Legal
Privacy Policy
Last updated: July 12, 2026
How to read this. When a farm signs up, the farm business is the owner of the account and controls the data in it. Fruition acts as a service provider that stores and processes that data on the farm's behalf — including information about the farm's employees and its customers. If you are a worker invited to a farm's account, that farm decides what is tracked and who can see it; questions about your own data should go to your employer first, and to us at the address below.
1. Information We Collect
Account and profile
- Name, username, email address, and (optionally) phone number.
- Farm business details: farm name, business address, city/state, phone, and email.
- Emergency contact — a name and phone number you may provide for a worker. This is information about a third person, so please only enter it with their knowledge.
- Password (stored only as a one-way hash — see "How We Protect Your Information"), and, if you enable it, two-factor login settings.
- Role and employment details you or your employer enter: worker type, start date, pay frequency, overtime eligibility, and linked payroll identifiers.
Employee and labor data
- Time-clock records: clock-in / clock-out times, breaks and lunches, and total hours.
- Pay information: hourly wage rate, overtime multipliers and thresholds, commission rates, and per-employee mileage rates.
- Calculated pay: market-session pay, commission, mileage reimbursement amounts, and payroll runs (gross pay, regular and overtime hours, net pay, and pay-period dates) synced from QuickBooks.
- Mileage entries: start and end addresses, distance, reimbursement rate and amount.
- Purchase reimbursements, including receipt files you upload.
- Schedules, task assignments, task timers, time-off and shift-swap requests, and any notes attached to them.
Location data
- Precise (high-accuracy) GPS coordinates, collected during an active market session or a manually started farm trip. See Section 4 for full details, including background collection.
Farm and cultivation data
- Operational records you enter: harvests, production and inoculation runs, blocks and batches, strains, spawn and culture inventory, waste and contamination logs, cash-box and till counts, expenses, and environmental readings.
Financial and customer data
- Sales, orders, and payment records, and customer profiles, imported from your connected Square account (customer names, emails, phone numbers, purchase history, and invoice / accounts-receivable balances).
- Accounting data exchanged with QuickBooks Online, and time-clock data exchanged with QuickBooks Time.
- Wholesale customers and sales prospects you add: business name, contact name, phone, email, website, and notes.
- Bank-connection metadata via Plaid: the financial institution, account name, type, and the last four digits (the "mask") of an account. We do not receive or store full bank account numbers or routing numbers.
- Subscription billing handled by Stripe. Card details are entered directly with Stripe and tokenized; we never receive or store full card numbers.
Customer information held for farms
Where a farm connects Square or adds wholesale contacts, the customer and prospect information above belongs to that farm. We store and process it as a service provider so the farm can run its business (sales analysis, invoicing, outreach). We do not use it for our own marketing.
Communications
- Team chat messages and direct messages sent between users on a farm.
- A notification log recording alerts and messages we send on the farm's behalf — including the recipient's phone number or email address, the message content, the delivery channel, and delivery status.
- Conversations with the in-app AI assistant (see Section 5).
Device and technical data
- Push-notification tokens and a hashed device identifier used to deliver alerts.
- App/client health signals such as your browser or app user-agent string and cache/version information, used for troubleshooting and reliability.
- IP address and a username snapshot recorded in the security audit log for sensitive actions.
- Error and performance diagnostics captured by our monitoring provider when something breaks (see Section 6).
Camera
The app uses the camera to scan QR codes on cultivation labels. QR codes are decoded on your device and only the decoded label reference is used to look up a record — no photo is uploaded or stored for QR scanning. Separately, if you attach an image to a message in the AI assistant, that image is handled as described in Section 5.
Connected equipment (IoT)
If you connect grow-room hardware, we store the credentials or access tokens needed to read from and control those devices (AC Infinity controllers and Tuya smart devices), along with the device readings and on/off commands.
2. How We Use Information
We use the information above to:
- Provide, operate, secure, and improve the Fruition platform.
- Run time-clock, scheduling, payroll, commission, and mileage-reimbursement features.
- Calculate driving mileage and show supervisory market-session tools (Section 4).
- Sync with the accounting, point-of-sale, banking, and time-tracking services you connect.
- Answer your questions through the AI assistant when you use it (Section 5).
- Send operational alerts and messages you or your farm have configured (push, email, or SMS).
- Monitor system health, diagnose errors, prevent abuse, and enforce our Terms.
We do not use your information for advertising, and we do not sell it. See Section 8.
3. Sharing With Service Providers
We share information with the third-party providers below only as needed to deliver the features you use. Each is an independent company governed by its own privacy policy. We do not sell your data to any of them or authorize them to use it for their own marketing.
| Provider | What we share with them | Policy |
|---|---|---|
| Anthropic (Claude AI) | The farm data needed to answer your AI questions — which can include customer names, accounts-receivable balances, employee names, wages and hours, and profit-and-loss figures — plus any image you attach. See Section 5. | anthropic.com/legal/privacy |
| Square | OAuth authorization to your Square account; we import your sales, orders, invoices, and customer profiles. | squareup.com/legal/privacy |
| Intuit — QuickBooks Online | Accounting records (expenses/purchases) and employee time and payroll data exchanged with your QuickBooks company. | intuit.com/privacy |
| Intuit — QuickBooks Time | Employee time-clock data (clock in/out, breaks) exchanged with QuickBooks Time. | intuit.com/privacy |
| Plaid | Bank-linking authorization; we receive institution, account name/type, and last-four mask only — no full account numbers. | plaid.com/legal |
| Stripe | Subscription billing: your email and farm name, and a tokenized payment method. No full card numbers pass through us. | stripe.com/privacy |
| AC Infinity | Controller credentials/token and device commands and readings for grow-room automation. | acinfinity.com/pages/privacy-policy |
| Tuya | Signed API calls to read and control connected smart devices (device IDs, commands, state). | tuya.com/privacy_policy |
| Google Maps Platform | Address text you type for autocomplete, farm-address geocoding, place lookups for prospects, and map display of the live market view. | policies.google.com/privacy |
| Resend | Recipient email address, subject, and body of transactional emails (invites, alerts). | resend.com/legal/privacy-policy |
| Twilio | Recipient phone number and message content for SMS alerts. | twilio.com/legal/privacy |
| Expo (with Apple APNs / Google FCM) | Your device push token and notification payload (title, body, badge, deep link), relayed to Apple or Google to deliver push notifications. | expo.dev/privacy |
| DigitalOcean | Cloud hosting; all Fruition data is stored on their U.S. infrastructure. | digitalocean.com/legal/privacy-policy |
| Sentry | Error and performance diagnostics (stack traces, request metadata, a sample of performance traces) to help us fix problems. Configured not to attach user personal data by default. | sentry.io/privacy |
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this policy).
4. Location Data (Important)
Fruition collects precise GPS location to calculate driving mileage for reimbursement and to power a live market-session view for the farm owner. Please read this carefully.
Location data is used for two purposes:
- Mileage reimbursement — consecutive location points are used to measure the distance driven during a trip.
- A live supervisory view — during an active market session, the farm owner can see a real-time map showing the worker's current location pin and the route "breadcrumb" trail of the trip. This oversight view is limited to the farm owner.
Each location point stored includes latitude, longitude, accuracy, a timestamp, the worker's name, and the associated session or trip.
Consent and control. Location tracking is tied to a per-user consent setting and to your device's location permission. You can decline or revoke location permission at any time in your device settings; doing so disables mileage and live-map features but does not otherwise limit the platform. Farm owners are responsible for informing their workers about location tracking and for complying with applicable employment and privacy laws (see our Terms of Service).
Retention of location data. Location points are retained with the trip or session they belong to. Fruition does not currently run an automatic, time-based deletion of location points — they remain until the related session, trip, or account is deleted, or until an administrator purges them. If you would like your location history removed, contact us or your farm owner.
5. Artificial Intelligence ("Ask Fruition")
Fruition includes an optional AI assistant that answers questions about your farm. To generate answers, the assistant sends relevant farm data to Anthropic, the maker of the Claude AI models, which processes it on our behalf. You should understand what this can include:
- For a farm owner, the data sent to Anthropic to answer a question can include customer names, accounts-receivable and invoice balances, employee names, wage rates, hours worked, sales figures, and full profit-and-loss numbers, as well as harvest and production data.
- For a worker (non-owner), the assistant is restricted: it does not expose wages, other employees' pay, customer financials, invoices, or profit-and-loss data. Workers' questions are limited to grow-room status, their own schedule, and harvest/waste activity.
- If you attach an image, the image is sent to Anthropic to answer your question. A small thumbnail of that image is saved with your conversation in our database so you can see it later; the full-resolution image is not stored by us.
- Your conversation history is stored so the assistant has context, and a short summary of useful facts may be generated (also via Anthropic) and reused to personalize future answers.
Anthropic's handling of this data is governed by its privacy policy. Use of the AI assistant is optional — if you do not use it, no farm data is sent to Anthropic for this purpose.
6. How We Protect Your Information
We use a range of safeguards. To be transparent, here is specifically what we do:
- Passwords are stored only as a one-way hash using scrypt (the default in our web framework); we never store passwords in readable form.
- Third-party access tokens for integrations such as Square, QuickBooks, QuickBooks Time, and AC Infinity are encrypted at rest using Fernet (AES-128-CBC with HMAC authentication), with the encryption key held in the server environment rather than the database.
- Encryption in transit: all connections to Fruition use HTTPS/TLS, and the site sends HTTP Strict Transport Security headers.
- Tenant isolation: each farm's records are separated from other farms by application-enforced scoping (a farm identifier applied to every query) within a shared database.
- Account protections: session cookies are HttpOnly and same-site restricted, forms are protected against cross-site request forgery, login attempts are rate-limited, and an optional two-factor login sends a one-time code to your email.
- Auditing: sensitive actions are recorded in a security audit log.
No system is perfectly secure, and we do not claim protections we do not have — for example, we do not represent that data is encrypted at the disk or database-storage level. We work to protect your information but cannot guarantee absolute security.
7. Data Retention and Deletion
We keep your information for as long as your account is active and as needed to provide the service. You can delete your account yourself from within the app (Account settings), and here is what that does:
- Farm owner deletion removes the entire farm workspace — every record tied to that farm, including employees, customers, sales, invoices, harvests, messages, and location history — permanently.
- Worker (non-owner) deletion permanently deletes your personal, device, location, and pay records, disables your login, and removes your name from shared business records (replacing it with "Deleted User"). Business and bookkeeping records that must stay on the farm's books — such as completed sales and harvest logs — are retained but disassociated from your identity.
Some records may be retained where required by law, for legitimate business or tax purposes, or to resolve disputes. You may also contact us at the address below to request access to or deletion of your information; if you are a worker on a farm's account, we may direct or coordinate the request with your farm owner, who controls that account.
8. No Sale of Data; No Advertising or Tracking
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Fruition contains no advertising SDKs, no analytics or tracking pixels, and no third-party trackers. The mobile app does not use the advertising identifier (IDFA) and performs no cross-app tracking. Data is collected only to run the features described in this policy.
9. Children's Privacy
Fruition is a business tool intended only for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, make reasonable efforts to notify account owners. Continued use of Fruition after an update takes effect means you accept the revised policy.
Contact Us
Questions about this policy or your data? Reach out and we will respond.
Hidden Pearl Mushrooms LLC (operator of Fruition)
Email: support@fruitiongrower.com
Mailing address: [Add business mailing address]
Website: fruitiongrower.com